Security

The measures protecting the data companies upload to GRATOX. All of them are implemented: intentions are not listed here.

In force since 2026-08-21.

Who can get in

Two-step verification on every account

Not just administrative ones. A code is emailed on sign-in, and a trusted device can be remembered so it is not asked every time.

Company separation inside the database

Each company reaches only its own data, and the restriction is enforced by the database, not the application. Even a badly written query cannot return another company's data.

Per-module and per-project permissions

On top of the three account levels, each person is enabled only for the modules and projects that concern them.

How the data is protected

Encryption in transit and at rest

All traffic goes over HTTPS, and storage is encrypted at the database and file providers.

National ID numbers are stored encrypted, column by column

With AES-256-GCM and a key that lives outside the database. Anyone obtaining a full copy of the database could not read a single ID number.

Single-use links are not stored as-is

Invitations and email approval links are stored as a cryptographic digest, not in the clear.

What gets recorded

An audit trail not even our own server can alter

Who changed what, when and from where. Permission to modify or delete those records is revoked even for the service account: it can be demonstrated by attempting it in front of whoever asks.

Records are kept for 24 months

With automatic purging when they expire, keeping separately whatever must survive as evidence.

Continuity

Daily backups, retained for seven days

Which means that, in the worst case, the maximum data loss would be 24 hours.

Incident log with notification within 24 hours

Should a breach occur, it is logged with its cause and consequences, and the clock to notify the affected company starts when it became known.

What is not in place yet

  • · GRATOX does not yet hold ISO 27001 or SOC 2 certification.
  • · The audit trail begins on 19 August 2026. There is no change history before that date.
  • · Data is currently processed in a single region. There is no data residency in Chile.

Is your procurement team missing something? Write to us and we will answer in writing: contacto@gratox.net